Bug 1338646

Summary: CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
Product: [JBoss] JBoss Enterprise Web Server 2 Reporter: Michal Karm Babacek <mbabacek>
Component: mod_clusterAssignee: Jean-frederic Clere <jclere>
Status: CLOSED ERRATA QA Contact: Michal Karm Babacek <mbabacek>
Severity: medium Docs Contact:
Priority: medium    
Version: 2.1.0CC: bbaranow, bmaxwell, bperkins, cdewolf, csutherl, dandread, darran.lofthouse, jawilson, jclere, jpallich, lgao, myarboro, pgier, psakar, pslavice, rnetuka, rsvoboda, security-response-team, twalsh, vtunka
Target Milestone: DR02Keywords: Security, SecurityTracking
Target Release: 2.1.1   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: 1326328 Environment:
Last Closed: 2016-08-22 18:10:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1326328    
Bug Blocks: 1326320    

Description Michal Karm Babacek 2016-05-23 08:06:25 UTC
+++ This bug was initially created as a clone of Bug #1326328 +++

eap-6.4.z tracking bug for mod_cluster: see blocks bug list for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes
in the blocked bugs.

NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.

NOTICE: THIS BUG HAS THE DEFAULT OWNER (jboss-set) OVERRIDDEN BECAUSE IT WAS A MAILING LIST!  PLEASE CONTACT secalert IF THIS CONFUSES YOU.

[bug automatically created by: add-tracking-bugs]

--- Additional comment from JBoss JIRA Server on 2016-05-20 05:42:27 EDT ---

Radoslav Husar <rhusar> updated the status of jira MODCLUSTER-488 to Reopened

Comment 2 errata-xmlrpc 2016-08-22 18:10:17 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2016-1650.html